You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- name: Plan for unified security operations ## NEW article that covers specific to USX all up and link out to service topics
46
+
href: /defender-xdr/prerequisites ## PLACEHOLDER LINK
47
+
- name: Deploy ## Need new high level article. Put post deployment links at the end of article. Single article outlining deployment steps for Defender portal services. Point to services for more details. NEW article title: Deploy the Microsoft unified security operations
48
+
Items:
49
+
- name: Connect Microsoft Sentinel to Microsoft Defender
50
+
href: /defender-xdr/microsoft-sentinel-onboard
51
+
- name: Prevent attacks ## (Pre-breach) - Renamed from reduce risks. one article that summarizes how to do that with USX
52
+
items:
53
+
- name: Overview ## NEW Single article or perhaps a couple of articles that summarize our pre-breach protection philosophy, with links to relevant service articles. The article should align with the info about preventing attacks that;s in the datasheet. "Through a single portal, continuously monitor your digital environment, assess risk, and implement posture improvements using security controls across all platforms, cloud, and hybrid infrastructure".
54
+
href: /azure/sentinel/sap/deployment-attack-disrupt ## PLACEHOLDER LINK
55
+
- name: Microsoft Secure Score ## Write a single article or two that condenses all the info in the Protect against threats/Microsoft Secure Score section. Or because this is going away, we just link in all the articles? Or put them in reference?
- name: Detect threats ## Have each writer provide article and then we summarize in one article. Our outline and scope should align to datasheet: "Get visiblity into, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments"
68
+
href: /azure/sentinel/threat-detection ## PLACEHOLDER LINK
69
+
- name: Hunt for threats ## Seperating this out because per PM hunting might happen in different scenarios. Also wanting it higher level as advanced hunting is one of the things highlighted for USX.
70
+
items:
71
+
- name: Overview
72
+
href: /defender-xdr/advanced-hunting-overview ## PLACEHOLDER - Need overview article about the hunting features across services. Advanced hunting, custom detections, hunts in Sentinel
73
+
- name: Search with advanced hunting
74
+
items:
75
+
- name: Overview
76
+
href: /defender-xdr/advanced-hunting-overview
77
+
- name: Advanced hunting in the Microsoft Defender portal
- name: Investigate incidents ## could be incidents, threats, posture findings. Need an overview article for USX. Current overviews (XDR/Sentinel) don't appear to be updated for USX.
98
+
items:
99
+
- name: Overview
100
+
href: /defender-xdr/investigate-incidents ## Would need update to apply to USX. Per Dianne, this isn't XDR specific.
101
+
- name: Alerts, incidents, and correlation
102
+
href: /defender-xdr/alerts-incidents-correlation
103
+
- name: Manage incidents
104
+
href: /defender-xdr/manage-incidents
105
+
- name: Investigate alerts
106
+
href: /defender-xdr/investigate-alerts
107
+
- name: Investigate incidents in Copilot for Security ## This article is specific to Sentinel in the context of using outside of USX and with XDR in USX. We don't think it applies to Sentinel only but need to confirm with PM. Austin thought title w/o mentioning Sentinel is misleading. We might need to leave this out of TOC or as part of plan/deploy to integrate Sentinel w/ Copilot features.
108
+
href: /azure/sentinel/sentinel-security-copilot
109
+
- name: Investigate with Microsoft Copilot in Microsoft Defender ## Copied entire section from XDR TOC
- name: Manage your unified SOC ## Need article w/ overview about settings? What else needs to go here? Several other things like permissions and costs would get referenced by planning guide.
162
+
items:
163
+
- name: Manage multiple tenants ## Work will start soon to integrate Sentinel into one or more of these articles. Copied in entire section from XDR library
title: Microsoft unified security operations platform # < 60 chars
4
+
summary: The unified security operations platform brings together the full capabilities of Microsoft Sentinel, Defender XDR, and generative AI. # < 160 chars
5
+
6
+
metadata:
7
+
title: Microsoft unified security operations platform documentation # Required; page title displayed in search results. Include the brand. < 60 chars.
8
+
description: The unified security operations platform brings together the full capabilities of Microsoft Sentinel, Defender XDR, and generative AI. # Required; article description that is displayed in search results. < 160 chars.
9
+
ms.service: defender-xdr #Required; use either service or product per approved list.
10
+
ms.subservice: usx
11
+
ms.topic: landing-page # Required
12
+
ms.collection: usx-security # Optional; Remove if no collection is used.
13
+
author: cwatson-cat #Required; your GitHub user alias, with correct capitalization.
14
+
ms.author: cwatson #Required; microsoft alias of author; optional team alias.
title: What's new in the Microsoft unified security operations platform
3
+
description: Lists the new features and functionality in the Microsoft unified security operations platform
4
+
search.appverid: met150
5
+
ms.service: defender-xdr
6
+
ms.author: cwatson
7
+
author: cwatson-cat
8
+
ms.localizationpriority: medium
9
+
ms.date: 07/16/2024
10
+
manager: dansimp
11
+
audience: ITPro
12
+
ms.collection:
13
+
- M365-security-compliance
14
+
- tier1
15
+
- usx-security
16
+
ms.topic: conceptual
17
+
---
18
+
19
+
# What's new in the Microsoft unified security operations platform
20
+
21
+
<!--Need to define when something goes here versus other what's new articles. Maybe we just focus on updates within this library and things tied directly to USX (features that unblock onboarding, parity features with Sentinel, enhancements to core USX features?) -->
22
+
23
+
This article lists recent features added into the Microsoft unifed security operations platform within the Microsoft Defender portal, and new features in related services that provide an enhanced user experience in the platform.
24
+
25
+
The listed features were released in the last three months. For information about earlier features delivered, see our [Tech Community blogs](https://techcommunity.microsoft.com/t5/azure-sentinel/bg-p/AzureSentinelBlog/label-name/What's%20New).
26
+
27
+
For more information on what's new with other Microsoft Defender security products and Microsoft Sentinel, see:
28
+
29
+
-[What's new in Microsoft Sentinel](/azure/sentinel/whats-new)
30
+
-[What's new in Microsoft Defender XDR](/defender-xdr/whats-new)
31
+
-[What's new in Microsoft Defender for Office 365](/defender-office-365/defender-for-office-365-whats-new)
32
+
-[What's new in Microsoft Defender for Endpoint](/defender-endpoint/whats-new-in-microsoft-defender-endpoint)
33
+
-[What's new in Microsoft Defender for Identity](/defender-for-identity/whats-new)
34
+
-[What's new in Microsoft Defender for Cloud Apps](/cloud-app-security/release-notes)
35
+
36
+
You can also get product updates and important notifications through the [message center](https://admin.microsoft.com/Adminportal/Home#/MessageCenter).
37
+
38
+
39
+
## July 2024
40
+
41
+
-[SOC optimizations now generally available](#soc-optimizations-now-generally-available)
42
+
-[SAP Business Technology Platform (BTP) connector now generally available](#sap-business-technology-platform-btp-connector-now-generally-available-ga)
43
+
-[Microsoft unified security platform now generally available](#microsoft-unified-security-platform-now-generally-available)
44
+
45
+
### SOC optimizations now generally available
46
+
47
+
The SOC optimization experience in both the Azure and Defender portals is now generally available for all Microsoft Sentinel customers, including both data value and threat-based recommendations.
48
+
49
+
-**Use data value recommendations** to improve your data usage of ingested billable logs, gain visibility to underused logs, and discover the right detections for those logs or the right adjustments to your log tier or ingestion.
50
+
51
+
-**Use threat-based recommendations** to help identify gaps in coverage against specific attacks based on Microsoft research and mitigate them by ingesting the recommended logs and adding recommended detections.
52
+
53
+
The [`recommendations`](/azure/sentinel/soc-optimization/soc-optimization-api) API is still in Preview.
54
+
55
+
For more information, see:
56
+
57
+
-[Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access)
58
+
-[SOC optimization reference of recommendations](/azure/sentinel/soc-optimization/soc-optimization-reference)
59
+
60
+
### SAP Business Technology Platform (BTP) connector now generally available (GA)
61
+
62
+
The Microsoft Sentinel Solution for SAP BTP is now generally available (GA). This solution provides visibility into your SAP BTP environment, and helps you detect and respond to threats and suspicious activities.
63
+
64
+
For more information, see:
65
+
66
+
-[Microsoft Sentinel Solution for SAP Business Technology Platform (BTP)](/azure/sentinel/sap/sap-btp-solution-overview)
67
+
-[Deploy the Microsoft Sentinel solution for SAP BTP](/azure/sentinel/sap/deploy-sap-btp-solution)
68
+
-[Microsoft Sentinel Solution for SAP BTP: security content reference](/azure/sentinel/sap/sap-btp-security-content)
69
+
70
+
### Microsoft unified security platform now generally available
71
+
72
+
Microsoft Sentinel is now generally available within the Microsoft unified security operations platform in the Microsoft Defender portal. The Microsoft unified security operations platform brings together the full capabilities of Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Copilot in Microsoft Defender. For more information, see the following resources:
73
+
74
+
- Blog post: [General availability of the Microsoft unified security operations platform](https://aka.ms/unified-soc-announcement)
75
+
-[Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
76
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](/defender-xdr/microsoft-sentinel-onboard)
77
+
-[Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-in-microsoft-365-defender)
0 commit comments